PT-2025-36736 · FFmpeg+3 · Ffmpeg+3

·

CVE-2025-9951

·

Published

2025-01-01

·

Updated

2026-08-15

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: FFmpeg (affected versions not specified)
Description: A heap-buffer-overflow write exists in the jpeg2000dec component of FFmpeg. This issue could allow a remote attacker to potentially execute code or cause a denial of service through the channel definition cdef atom of JPEG2000 files.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

DoS

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-15661
CVE-2025-9951
DSA-5985-1
DSA-6007-1
GHSA-39Q3-F8JQ-V6MG
OESA-2026-3284
OESA-2026-3285
OESA-2026-3286
OESA-2026-3287
OESA-2026-3288
OPENSUSE-SU-2026:10866-1
OPENSUSE-SU-2026:10867-1
OPENSUSE-SU-2026:10890-1
OPENSUSE-SU-2026:11515-1
OPENSUSE-SU-2026:21211-1
SUSE-SU-2026:2444-1
SUSE-SU-2026:2445-1
USN-7830-1

Affected Products

Debian
Ffmpeg
Linuxmint
Ubuntu